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Description 

Background of the Invention 

[0001 ] The present invention relates to an illegal view 
and copy protection technique for a digital video system, 
and nnore particularly, to an illegal view and copy pro- 
tection method in a digital video system for preventing 
an illegal user from viev^ng the digital video system and 
copying therefrom, by setting a descrambling method 
which decrypts split keystreams adopting a smart card. 
[0002] In a general digital video system, there has 
been a keen interest in implementing a conditional ac- 
cess (CA) system for an illegal viewing protection. 
[0003] In such a CA system, a broadcasting signal is 
scrambled at charged channels such as in a cable tele- 
vision or a satellite broadcasting service to be broad- 
casted. Therefore, only a user who paid nonnatty can 
view a program properly through descrambling. 
[0004] For example, a satellite broadcasting receiver 
or a Grand Alliance (GA) system, which is a standard of 
an advanced television (ATV) in U.S.A. has a function 
for supporting a CA. Also, scrambling/descrambling ap- 
paratus, such as a video cipher manufactured by Gl, 
which can be used for a satellite broadcasting, have 
been commonly used. 

[0005] Video cipher manufactured by Gl is generally 
used for the scrambling system for a CA system, which 
is based in U.S. Patent No. 4,61 3,g01 by Gilhousen, dis- 
closing a system and method, in which a TV signal trans- 
ported via a nonnal user's descrambler is scrambled In 
a charged TV system to be broadcasted and then Is se- 
lectively descrambled in the user's descrambler. A video 
cipher system for performing a descrambling is imple- 
mented by adopting a smart card, which is disclosed in 
U.S. Patent No. 5,111,504. This is implemented such 
that the system proposed by Gilhousen is partitioned in- 
to two parts, that is, an infomriation processor corre- 
sponding to a descrambler and a security element which 
can be replaced by a smart card. 
[0006] Therefore, by adopting the above method, the 
scrambling system is implemented as shown in FIG. 1 , 
and the descrambling system is implemented as shown 
In FIG. 2. 

[0007] In other words, a conventional illegal viewing 
protecting apparatus for a digital video system includes 
a scrambler 101 for scrambling a TV signal In accord- 
ance with a common category key (OK) and an initiali- 
zation vector (PK) and outputting the scrambled TV sig- 
nal (SVq) and scrambling Information Eu(d)Eu(S)(C*Q 
and Eqk(PK), a smart card 103 for encrypting informa- 
tion for descrambling, A(D) and A(S), with respect to de- 
scrambling information U(S), and an information proc- 
essor 1 02 for decrypting the infomriation for descranv 
bling, Ea(d)[Ea(S)(WK)], to descramble the TV signal 
(SVo) transported from scrambler 1 01 and restoring the 
same into original TV signal DV^. 
[0008] Here, A(D) is an authentication key of informa- 



tion processor 102, A(S) is an authentication key of 
smart key 103, U(D) is a unit key of information proces- 
sor 102, and U(S) is a unit key of smart key 103. 
[0009] At this time, scrambler 1 01 includes a first en- 

5 crypter 1 1 1 for encrypting a common category key (CK) 
with respect to descrambling infomiation U(D) and U(S), 
a second encrypter 112 for encrypting an initialization 
vector (PK) with respect to the common category key 
(CK), a third encrypter 113 for encrypting the Initializa- 

10 tion vector (PK) vwth respect to the output Eq^{PK) of 
second encrypter 11 2, and a scrambling executing party 
1 1 4 for scrambling a TV signal V, in accordance with the 
output WK of third encrypter 113. 
[0010] The operation of the conventional apparatus 

'5 having the aforementioned configuration will now be de- 
scribed. 

[001 1 ] First, in the case of transporting a TV signal in 
a transport system, scrambler 1 01 operates such that 
the common category key (CK) is encrypted with re- 

20 spect to the descrambling information U(D) and U{S) by 
first encrypter 111, the initialization vector (PK) is en- 
crypted with respect to the common category key (CK) 
by second encrypter 11 2, the initialization vector (PK) is 
encrypted with respect to the output Eck(P*^) second 

25 encrypter 11 2 by third encrypter 1 1 3, to then be output 
to scrambling executing party 114. 
[0012] At this time, scrambling executing party 114 
scrambles theTV signal Vj in accordance with the output 
WK of third encrypter 113. Here, the scrambling infor- 

30 mation WK is expressed in Eeck(pk)(P*^)- 

[0013] Accordingly, scrambler 101 transports infor- 
mation Ey(Qj Ey(s)(CK) encrypted with respect to the 
common category key (CK), the Information Eck(PK) 
encrypted initialization vector (PK) and the scrambled 

35 TV signal SV^, to infomriation processor 1 02. 

[0014] In case of descrambling the scrambled TV sig- 
nal SVq, smart card 103 encrypts the infomriation WK 
necessary for descrambling with respect to authentica- 
tipn infomriation A(D) of infomiation processor 102 and 

40 its own authentication information A(S), and then gen- 
erates the encrypted descrambling infomriation ^a{0) 
l^Ais)(^^)] information processor 102. 
[0015] Accordingly, infomriation processor 102 de- 
crypts the encrypted descrambling infomriation ^a{0) 

45 [E;^s)(WK)1 generated from smart card 103 and de- 
scrambles the TV signal SV^ transported from scram- 
bler 101 using the encrypted descrambling Infomriation 
^ap)[^a(S)(WK)], thereby restoring the same into the 
original TV signal DV^. 

50 [0016] Here, the encryption in transporting the infor- 
mation between infomiation processor 102 and smart 
card 1 03 is adopted for enhance the security from the 
illegal view and copy. 

[0017] For example, the specification of a GA-HDTV 
55 system supports the CA system and includes various 
functions necessary for transport protocols. 
[0018] These functions are flexible and useful in that 
they support all possible descrambling methods and key 
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encryption methods, and bitstreams are selectively 
scrambled so that a CA function can be adopted in the 
unit of an element stream. 

[0019] Here, the scrambling randomizes data bit- 
stream according to information data, and the encryp- 5 
tion converts information data in order to protect the in- 
fomnation data from illegal users. 
[0020] In other words, the CA system makes the 
transported data random and disables the illegal users' 
decoders to be decoded improperly by means of a 
scrambler but allows the legal users' decoders to de- 
code the received TV broadcasting signals properly by 
supplying infomnation for Initializing a descrambler cir- 
cuit. 

[0021] The CA transport MPEG protocol for such op- 
eration is implemented by the format shown in FIG. 3 
and supports the CA function as follows. 
[0022] First, a transport-scrambling-control field of 2 
bits notifies whether or not a transport stream is scram- 
bled and which scrambling key is used. 
[0023] Second, each data is inserted into the GA 
transport system using a transport-private-data field po- 
sitioned within adaptation header of the transported 
stream, and encrypted scrambling infomnation is stored 
in the field. 

[0024] The CA transport MPEG protocol transports a 
transport header, a packettzed elementary stream 
(PES) and audio and video data independently or con- 
currently. The transport protocol includes a header link 
header region, an adaptation header region and a pay- 
load region. 

[0025] Here, the link header has a length of 4 bytes 
and the adaptation head has a variable length. 
[0026] The transport-scrambling-control field is in- 
serted Into the link header. A field value of "00" is rec- 
ognized as being not scrambled, "1 0" is recognized as 
being an even key, "IT is recognized as being an odd 
key, and "01" is recognized as being reserved. 
[0027] The adaptation header includes a flag bit and 
transport-private-data field, and the flag bit includes 
transport-private-data flag of one bit. The PES header 
of the CA transport MPEG protocol shown in FIG. 3 Is 
constructed as shown in FIG. 4. 
[0028] A field for a digital storage media (DSM) such 
as a digital video cassette recorder (DVCR) exists in the 
PES header. Such a field Include a PES header flag re- 
gion having a length of 14 bits and a PES header field 
having a variable length. The PES header flag region 
includes a 1-bit copyright (CR) flag, a 1-bit original-or- 
copy flag, a 2-bit PD flag, a 1 -bit TM flag and a 1 -bit AC 
flag. 

[0029] The PES header field has a variable length and 
its region is partially set by the PD, TM and AC flags 
contained in the PES header flag region. 
[0030] In other words, PTS/DTS regions do not exist 
in the PES header field if the PD flag value is "00," PTS/ 
DTS of 40 bits exist if the PD flag value is "10," PTS/ 
DTS of 80 bits exist if the PD flag value is "1 1 ." A DSM 



trick mode does not exist if the TM flag value is "0," and 
the DSM trick mode becomes 8 bits if the TM flag value 
is "1 ." Also, if the AC flag is set to "1 an additional copy 
infomnation field becomes 8 bits. 
[0031] The scrambling infomnation is transported by 
adopting the above-described format, and the descram- 
bling process using the information is shown in FIG. 5. 
[0032] Here, since the descrambling system decrypts 
the next encrypted key together with the key being used 
for the current descrambling, the descrambler stores at 
least two keys, that Is, an odd key and an even key. 
[0033] Also, the scrambling system sets a value of the 
transport-scrambling-control field within the link header 
according to the descrambling method of the current 
transport stream to then transport the same. 
[0034] Accordingly, the descrambler detennines an 
even key or an odd key according to the value of the 
transport-scrambling-control field of the decrypted 
transport head from the received data and then de- 
scrambles the received data to then be decrypted. 
[0035] In other words, when the data having the for- 
mat shown in FIG. 5 is transported and descrambler de- 
scrambles the Kgrv^-th frame with the odd key according 
to the value of the transport-scrambling-control field de- 
crypted in smart card, smart card decrypts the transport- 
scrambling-control field of Kgn-th frame to be de- 
scrambed next. These operations are sequentially per- 
formed. 

[0036] An ATV decoder for perf onming the CA function 
may be implemented as shown in FIG. 6. The ATV de- 
coder 110 incorporates a descrambler necessitating a 
fast operation into a transport demultiplexer 105 and 
performs the descrambling by a DES algorithm or a 
stream cipher algorithm using a PN sequence. The key 
encrypted by ATV decoder 110 Is decrytped in smart 
card 103. Here, the interface between smart card 103 
and ATV decoder 110 is executed in accordance with 
the ISO-781 6 standard specification. 
[0037] In other words, in the an-angement shown in 
FIG. 6, a signal received from a tuner is demodulated in 
a demodulator & error corrector 1 04 and then the errors 
generated during transport are corrected by an RS de- 
coding and are input to transport demultiplexer 105 of 
ATV decoder 1 1 0 to then be descrambled. 
[0038] At this time, a microcontroller 1 09 operates de- 
scrambled control and data and transports the encryp- 
tion infomnation for descrambling to smart card 103. 
Smart card 1 03 decrypts the transported encryption in- 
formation to transport the same to ATV decoder 1 1 0. 
[0039] At this time, transport demultiplexer 105 re- 
stores a compressed video and audio signals, control 
signal and data according to the descrambling infonma- 
tion. 

[0040] Accordingly, a video decoder 107 extends the 
compressed video signal and temporarily stores the ex- 
tended signal in a memory 1 06 and then outputs the 
stored data to display a video. An audio decoder 1 08 
extends the compressed audio signal and then repro- 
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duce an audio. 

[0041 ] Also, microcontroHer 1 09 reads the control sig- 
nal and data output from transport demultiplexer 1 05 
and controls the operations of video decoder 1 07 and 
audio decoder 108. 

[0042] Among various methods used for encryption, 
a blockcipher algorithm such as DES and a stream-ci- 
pher algorithm using the PN sequence are most widely 
used. 

[0043] However, since these methods perform en- 
cryption and decryption only with a encrypted signal, a 
key management and a key distribution are hard to ac- 
complish. 

[0044] Therefore, in order to solve the above problem, 
a public key encryption method has been proposed In 
U.S. Patent No, 4,200,770. This method perfomns en- 
cryption using a publk; key and performs decryption us- 
ing his own secret key. 

[0045] The public key encryption method has been 
improved and implemented as an encryption system, 
which is known as an RSA encryption algorrthm dis- 
closed in U.S. Patent No. 4,405,829. However, this pub- 
lic key encryption method is not suitable for fast encryp- 
tion. 

[0046] The CA system aims to protect an illegal view- 
ing. However, programs distributed through a DSM such 
as a DVCR cannot be protected from the illegal copying. 
[0047] In other words, the protection of the program 
distributed by a recording medium such as DSM means 
the illegal copying protection. However, the copy protec- 
tion method adopted in a conventional analog VCR sys- 
tem is difficult to be adopted in a digital storage media. 
Also, research into the copy protection method for DSM 
has not yet been developed well. 

Summary of the Invention 

[0048] Preferred and particular embodiments of the 
present invention, which is defined in its broadest aspect 
in claim 1 , seek to address the problems of the prior art 
and provide illegal view and copy protection method in 
a digital video system and a controlling method thereof 
for protecting illegal view and copy, in which encrypted 
key is decrypted in a smart card by transporting a scram- 
bled bitstream and the encrypted key used for scram- 
bling to different paths and the bitstream is descrambied 
in accordance with the infomiation, and normal decod- 
ing is not performed only by the bitstream. 
[0049] Further embodiments of the present invention 
adopt a smart card in the CA system so that the charge 
is automatically checked to enforce the pay per view 
(PPV) function and to upgrade the perfonnance of the 
system by adding various functions by way of replace- 
ment of the smart card. 

[0050] Still other embodiments of the present inven- 
tion reduce the key quantity of the data to be protected 
greatly by splitting the transported data and to make the 
system inoperative with an illegal smart card by auto- 



matic performance of authentication and key exchange 
during power-on or connection to a digital recording /re- 
production device for recording, thereby increasing the 
reliability of the protection function. 

5 [0051] The present invention provides an illegal view 
and copy protection method in a digital video system, 
including: a determination step for determining whether 
received data has been scrambled; a reproduction step, 
if the received data was detennined to be scrambled da- 

10 ta in the determination step, splitting the scrambled data 
into a bitstream and a keystream for decrypting the split 
keystream for reading in key infomnation, and descram- 
bling the split bitstream according to the read In key in- 
fomnation for displaying the bitstream on a display; a re- 

15 cording step for, if the received data was determined to 
be scrambled data in the detemnination step, recording 
the scrambled data on a recording medium either as 
scrambled data of a bitstream and a keystream accord- 
ing to a recording or copying mode, or after splitting the 

20 scrambled data into a bitstream and a keystream, en- 
crypting the split keystream, and mixing the encrypted 
keystream with the bitstream; and a transporting step, 
if the received data was detemiined to be scrambled da- 
ta in the determination step, splitting the scrambled data 

25 into a bitstream and a keystream tor transporting the 
split keystream either after decrypting the split key- 
stream with respect to key information from recording 
side according to a PPC mode or a back-up copy mode, 
or after decrypting the split keystream two times with re- 

30 spect to key infomnation contained therein and key in- 
fomnation from recording side, thereby the reproduction 
step, the recording step and the transporting step can 
be performed simultaneously or selectively. 
[0052] Embodiments of the invention provide an ille- 

35 gal view and copy protection method in a digital video 
system, including: a reproduction step, on reception of 
scrambled data, splitting the scrambled data into a bit- 
stream and a keystream for decrypting the split key- 
stream for reading in key infomnation, and descrambling 

40 the split bitstream according to the read in key infonma- 
tion for displaying the bitstream on a display; and a re- 
cording step for, on reception of scrambled data, record- 
ing the scrambled data on a recording medium as 
scrambled data of a bitstream and a keystream; thereby 

45 the reproduction step and the recording step can be per- 
formed simultaneously or selectively. 
[0053] Embodiments of the invention also provide an 
illegal view and copy protection method in a digital video 
system, including: a determining step for determining 

50 the mode of the keystream being a back-up copy mode 
or a PPC mode; a first transportation step for, if the mode 
was determined to be a PPC mode in the detemnining 
step, decrypting the keystream with respect to key in- 
formation from a recording side for transporting the key- 

55 stream; a first recording step for encrypting the key- 
stream transported in the first transportation step with 
respect to the key information from the recording side 
and inserting the encrypted keystream into a position 
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corresponding to an index code, for recording the key- 
streann together with a bitstream on a recording medi- 
unn; a second transportation step for, if the nnode was 
determined to be a back-up copy mode in the determin- 
ing step, decrypting the keystream for two times with re- 
spect to its own key inf omiatlon and the key information 
from the recording side for transporting the keystream; 
and a second recording step for encrypting the key- 
stream transported in the second transportation step 
with respect to the key information from the recording 
side and Inserting the encrypted keystream into the po- 
sition con^esponding to the index code, for recording the 
keystream together with the bitstream on a recording 
medium. 

[0054] Embodiments of the invention also provide an 
illegal view and copy protection method in a digital video 
system, including: a 'PPC* mode reproduction step for, 
having determined the recording medium being a 'PPC 
recording medium on detection of a keystream at repro- 
duction from a recording medium, encrypting the key- 
stream with respect to its own key infonnation and de- 
crypting the keystream with respect to its own key infor- 
mation for reading in the key information, for descram- 
bting the bitstream using both the read In key infon-nation 
and an index code; and a 'back-up copy* mode repro- 
duction step for, having determined the recording medi- 
um being. a 'back-up copy* recording medium on detec- 
tion of a keystream decrypted with respect to its own 
key information at reproduction from a recording medi- 
um, encrypting the keystream for two times with respect 
to its own key information and the key infomnation from 
a recording side and decrypting the keystream with re- 
spect to its own key infomnation for reading in the key 
infomnation, for descrambiing the bitstream using both 
the read in key information and an index code. 
[0055] Embodiments of the invention also provide an 
illegal view and copy protection device in a digital video 
system, including: demodulating & enror correcting 
means for modulating /demodulating an analog broad- 
casting signal and RS-decoding said signal; copy pro- 
tection processing means for transporting the output of 
said demodulating & error correcting means to a digital 
recording/reproduction device, splitting the scrambled 
recording signal reproduced from said digital recording/ 
reproduction device into a bitstream and a keystream, 
and encrypting the split keystream; decoding means for 
descrambiing the bitstream from said demodulating & 
error correcting means or the copy protection process- 
ing means according to descrambiing information; and 
a smart card for decrypting the encrypted keystream of 
sard copy protection processing means for applying to 
said decoding means as descrambiing information. 
[0056] Embodiments of the invention also provide an 
illegal view and copy protection device in a digital video 
system, including: first copy protection processing 
means for splitting reproduction data from a first digital 
recording /reproduction device into a bitstream and a 
keystream and encrypting the split keystream; first and 



second smart cards for decrypting encrypted keystream 
from said first copy protection processing means with 
respect to its own key infomnation and the key informa- 
tion from a recording side; and second copy protection 
5 processing means for encrypting the keystream from 
the first smart card trar^sported through the second 
smart card with respect to its own key information and 
transporting the encrypted keystream together with the 
split bitstream to a second digital recording/reproduction 
10 device, for recording on a recording medium. 

[0057] In a preferred embodiment, the copy protection 
processing means includes a RAM for storing intrinsk: 
key information of the smart card, an algorithm storage 
memory for storing an encryption algorithm, and a proo- 
fs essor for executing an encryption program of the algo- 
rithm storage memory with the key information of the 
RAM. 

[0058] Aforementioned copy protection processing 
means includes a CA function as well as an alt round 

20 program copyright protection function inclusive of illegal 
viewing protection and illegal copying protection. 
[0059] In a preferred embodiment, the smart card in- 
cludes a first algorithm storage memory for storing a de- 
cryption algorithm program for a bitstream, a second al- 

25 gorithm storage memory for storing a decryption algo- 
rithm program of its own key infomnation, a ROM for stor- 
ing its own key infomnation, and a RAM for temporarily 
storing key information of another smart card. 

30 Brief Description of the Drawings 

[0060] The above objects and advantages of the 
present invention will become more apparent by de- 
scribing in detail a preferred embodiment thereof with 
35 reference to the attached drawings in which: 

FIG. 1 is a block diagram of a general scrambler; 
FIG. 2 is a block diagram of a general descrambler; 
FIG. 3 illustrates a transport fomnat; 
40 FIG. 4 illustrates a PES header shown in FIG. 3 in 
detail; 

FIG. 5 illustrates the transport fomnat by key distri- 
bution; 

FIG. 6 is a block diagram of a conventional ATV de- 
45 coder; 

FIG. 7 is a block diagram of an illegal view and copy 
protection apparatus embodying the present inven- 
tion; 

FIG. 8 is a detailed block diagram of the copy pro- 
50 tection apparatus shown in FIG. 7; 

FIG. 9 Is a detailed block diagram of the smart card 
shown in FIG. 7; 

FIG. 10 illustrates the splitting of the bitstream 
shown in FIG, 8; 
55 FIG. 11 illustrates the format of the respective bit- 
streams; 

FIGS. 1 2 through 1 8 illustrate the connections state 
of a preferred embodiment of the present invention; 
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FIGS. 1 9 and 20 show the flow of signals for oper- 
ation of a preferred embodiment of the present in- 
vention; and 

FIG. 21 shows the flow of signals for key exchange 
and authentication according to a preferred embod- 
iment of the present invention. 

Detailed Description of the Invention 

[0061] The present invention is applicable to all re- 
cording/reproduction devices that can record and repro- 
duce a digital signal, and for the sake of convenience of 
explanation, descriptions shown hereinafter is for an 
embodiment in a case of DVCR, as an example. 
[0062] Accordingly, as shown in FIG, 7, the illegal 
view and copy protection apparatus in a digital video 
system according to an embodiment of the present in- 
vention, Includes a demodulator & error connector 1 for 
modulating/demodulating an analog broadcasting sig- 
nal and RS-decoding the signal, an ATV decoder 2 for 
descrambling the output of demodulator & error con-ec- 
tor 1 according to descrambling information, a copy pro- 
tection processor 4 for splitting the scrambled recording 
signal into a bitstream and a keystream and encrypting 
the split keystream, and a smart card 3 for decrypting 
the split and encrypted keystream of copy protection 
processor 4 and the index code of ATV decoder 2 and 
outputting descrambling infonmation KS to ATV decoder 
2. 

[0063] Copy protection processor 4, as shown in FIG. 
8, includes a RAM 1 7 for storing intrinsic key infomiation 
of the smart card, an algorithm storage memory 18 for 
storing an encryption algorithm, and a processor 1 9 for 
executing an encryption program of algorithm storage 
memory 18 with the key infomiation of RAM 17. 
[0064] Smart card 3, as shown in FIG. 9, includes a 
first algorithm storage memory 12 for storing a decryp- 
tion algorithm program for a bitstream, a second algo- 
rithm storage memory 13 for storing a decryption algo- 
rithm program of its own key infomnation, a ROM 14 for 
storing its own key infomnation, a RAM 15 for temporarily 
storing key information of another smart card, and a 
processor 11 for executing encryption or decryption with 
the storage algorithm of first and second algorithm stor- 
age memories 12 and 13 with respect to the key infor- 
mation stored in ROM 1 4 or RAM 1 5. 
[0065] At this time, processors 1 1 and 1 6 may be con- 
structed by wired logk; or may adopt a microprocessor. 
In case of adopting the microprocessor, the encryption 
algorithm for a smart card may be incorporated in a pro- 
gram. 

[0066] The operation and effect of the embodiment 
constructed as stated above will now be descn'bed. 
[0067] In the described embodiment, a GA bitstream 
is transported in the fomnat as shown in FIGS. 11 A 
through 11C, in which FIG. 11 A shows a unscrambled 
f onmat, FIG. 1 1 B shows a scrambled fomnat with respect 
to a bitstream, and FIG. 11C shows a fomiat in which 



the bitstream is selectively scrambled. 
[0068] In the described embodiment, if the GA bit- 
stream is scrambled, it is assumed that a protection of 
any kind will be applicable. 

5 [0069] Therefore, if scrambled stream data Sj^(BS) 
+EG(KS) of the format shown in FIG. 1 1 B or 1 1 C is input 
to copy protection processor 4, a splitter shown in FIG. 
10 splits the stream data into bitstreams Sks(BS)+IDX 
and keystreams EG(KS). Then, a recording mode is per- 

10 formed to encrypt again the split keystreams £^{KS) to 
then be transported to smart card 3. 
[0070] Here, as shown in FIG. 110, if the bitstreams 
are partially scrambled, the illegal view and copy pro- 
tection function is adoptable only to the scrambled por- 

15 tion, thereby performing a partial protection function. 
[0071] First, when non-scrambled bitstreanrts are 
transported as shown in FIG. 1 1 A, even if the bitstreams 
modulated/demodulated and decrypted in demodulator 
& error corrector 1 are input to copy protection processor 

20 4, the data is not transported to smart card 3. Either, 
ATV decoder 2 to which the bitstreams of demodulator 
& error corrector 1 are input does not transport the data 
to smart card 3 but decrypts the bitstream. 
[0072] Therefore, there is no restriction in view and 

25 copy. 

^ [0073] Here, the signal input from a tuner to demod- 
ulator & errorcorrector 1 and the video and audio signals 
output from ATV decoder 2 are analog signals. The sig- 
nal output from tuner Is a VSB-modulated signal from 

30 the GA-bitstream. 

[0074] Among input/output signals, bitstreams and 
keystreams are digital signals for DVCR. 
[0075] At this time, if the recording is perfomied, the 
bitstreams are recorded onto DVCR and the recorded 

35 bitstreams are played back from a general DVCR. 
[0076] In other words, even if non-scrambled MPEG 
bitstreams are input to copy protection processor 4 and 
passes through splitter as shown in FIG. 10, there is no 
data transported to smart card 3 due to no key infomna- 

40 tion, thereby allowing a free view and copy. 

[0077] Also, when the recording or copy protection 
functions are executed in the present invention, the split 
bitstreams and keystreams are transported to different 
lines from each other. The information on the copy pro- 

45 tection method is transported with an additional copy in- 
formation field within the PES header. 
[0078] At this time, even if the scrambled bitstreams 
having no encrypted key are transported to an illegal us- 
er of the public channels, the descrambling is not exe- 

50 cuted property in the state where the key infomiation is 
removed. 

[0079] Also, the split key is again encrypted to be 
transported. Thus, if there Is no decryption algorithm, 
bitstreams cannot be descrambled. 
55 [0080] Therefore, in the described embodiment, an 
arbitrary field is used in the MPEG transport protocol for 
the illegal view and copy protection, in which scram- 
biing-executed bitstreams adopts the copy protection 
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function. 

[0081] Rrst, if transport-scrannbling-control field is 
changed into a "not-scrambled" nnode, ATV decoder 2 
does not execute descrambling, so that the illegal user 
cannot operate the field. 5 
[0082] In such copy protection method, copy protec- 
tion or free-copy function is detemnined by the transport- 
scrambiing-control field. Therefore, the illegal user can- 
not release the copy protection function only by manip- 
ulating the field. 

[0083] Next, the illegal user may modify the additional 
copy Information field within the PES header, which con- 
verts the protection method. This method does not re- 
move the protection method itself, which does not cause 
a noticeable damage to the copy protection function. 
[0084] The copy protection method supported by the 
embodiment having the above features includes a "no 
copy" method, a "pay-per-copy (PPC)" method, and a 
"back-up copy" method, with the default of a pay-per- 
view (PPV) function and a pay-per-play (PPP) function. 
[0085] Here, the "no copy" method makes it complete- 
ly difficult to copy with another video tape. The "PPC" 
method is to pay per one copy. The "back-up copy" 
method allows a video tape played back from a first 
DVCR and copied from a second DVCR to be displayed 
nonmally only in the first DVCR but not in the second 
DVCR. 

[0086] A copy protection method embodying the 
present invention and the flow of the corresponding 
MPEG bitstreanns will now be described with reference 
to FIGS. 19 through 21. 

[0087] Here, FIG . 1 9 shows the flow of sig nals for op- 
eration of the copy protection processor during record- 
ing or playback mode, FIG. 20 shows the flow of signals 
for operation of the smart card corresponding to the 
copy protection processor, and FIG. 21 shows the flow 
of signals for key exchange and authentication during 
recording or playback operation. 
[0088] Rrst, referring to FIG. 19A, copy protection 
processor 4 to which bitstreams are input checks the 
presence or absence of key infomnation to detemnine 
whether it is scrambled or not, and detemriines whether 
the recording is the first recording or the copy recording 
if the key infonnation Is scrambled (SI 01). In other 
words, in the case of scrambled data, It is detected 
whether the data is transported in the streams of Sj^g 
(BS)+IDX format by splitting the data into bitstreams 8,^5 
(BS) and keystreams EG(KS). If the streams of 8^3(68) 
+IDX format are detected, the recording is determined 
to be the copy recording. If not detected, the recording 
is determined to be the first recording {S102). 
[0089] Accordingly, if the recording is detemnined to 
be the first recording, the mixed streams Sks(BS)+E^ 
(KS) of bitstreams and keystreams are recorded onto a 
tape (SI 06). If the recording is determined to be the 
copy recording, the bitstreams Sks(BS)+IDX with key- 
streams EG(KS) split, are transported to copy protection 
processor 8 of recording side and the keystreams E*^ 



(KS) are again encrypted with respect to the key infor- 
mation Ak (S105). Then, the encrypted keystreams Es. 
^AK[EG(KS)] are transported to smart card 7 of recording 
side via smart card 3, thereby allowing the recording on- 
to the tape in a VCR 9 of recording side (SI 06). 
[0090] On the contrary, FIG. 19B shows the signal 
flow in the case of the playback of the recorded tape 
with the same signal flow as shown in FIG. 1 9A, in which 
copy protection processor 4 splits and determines key- 
streams (SI 08) if bitstrean^ played back from VCR are 
input (SI 07), thereby determining whether the recording 
function is a "back-up copy" or not (S1 10). 
[0091] At this time, In step S110, the tape is deter- 
mined as a general recording tape, if there is no key in- 
fonnation, and the tape is detemnined as the first record- 
ing tape if encrypted keystreams E^(KS) are detected. 
Also, if the keystream Dsc'^EG(KS)] encrypted with re- 
spect to its own key information Ak, the tape is deter- 
mined as the recording tape of PPC function. If the key- 
stream Dsc'^E^CKS)] encrypted with respect to the key 
information Al of another smart card, the tape is deter- 
mined as the recording tape of back-up copy function. 
[0092] Accordingly, copy protection processor 4 
transports to ATV decoder 2 the bitstream (BS) in the 
case of a general recording tape, and the bitstream S^s 
(BS)+IDX with keystreams E<^{KS) split in the case of 
the recording tape of back-up copy function (SI 09). 
[0093] Copy protection processor 4 transports to 
smart card 3 the encrypted keystream Dsc^'<[EG(KS)] 
encrypted twice by the encryption algorithm E^c^i^^ j 
with respect to its own key infomnation Ak if the back-up 
copy function is adopted during the playback of the re- 
cording tape of copy protection function (S1 11 , S1 1 2 and 
S113). Also, copy protection processor 4 transports to 
smart card 3 the encrypted keystream Esc^'«[EG(KS)] 
obtained by encrypting keystream E^^(KS) by the en- 
cryption algorithm E^^^kc ) with respect to its own key 
infomnation Ak If the back-up copy function is not adopt- 
ed (S112andS113). 

[0094] While the above-described operations are per- 
fomned by copy protection processor 4, smart card 3 
performs the operations of the signal flow as shown in 
FIG. 20. To be detail, smart card 3 detemnines whether 
an index code IDX or keystream E^(KS) is input from 
ATV decoder 2 or not, by performing broadcasting or 
playback operation (S1 14 and S115). 
[0095] At this time, if the keystream E9(KS) is input 
instead of the index code IDX. smart card 3 having de- 
termined the broadcasting view of PPV function de- 
crypts the keystream E®(KS) by decryption algorithm 
D^{') with respect to the bitstream GA (S11 6) and Inputs 
the key information KS to ATV decoder 2 (S11 7). 
[0096] Accordingly, ATV decoder 2 reads the key in- 
formation KS of snnart card 3. determines a descram- 
bling method and descrambles the bitstream S^slBS) 
to output analog video and audio signals, thereby allow- 
ing a viewer to watch the broadcasting program. 
[0097] If it is detemnined that the index code IDX is 
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input in S115, snnart card 3 decrypts the keystream E^. 
c'^E^(KS)] input from copy protection processor 4 by 
decryption algorithm D^;y<(.) with respect to the key in- 
formation Ak (S118) and then detemnines whether the 
operation is a playback operation or a recording opera- 
tion (S119). 

[0098] At this time, if it is detenmined that the opera- 
tion is the playback operation in S11 9, smart card 3 de- 
crypts the keystream EG(KS) by decryption algorithm 
D®(-) with respect to the bitstream GA (S11 6) and inputs 
the key infonmation KS to ATV decoder 2 (S11 7). 
[0099] Accordingly, ATV decoder 2 reads the key in- 
formation KS of smart card 3, determines a descram- 
bling method and descrambles the bitstream Sks(BS) 
spilt in copy protection processor 4 by the detemntned 
descrambling method to output analog video and audio 
signals, thereby allowing a viewer to watch the recorded 
program of the tape. 

[0100] If it is determined that the operation is the re- 
cording operation in S1 19, smart card 3 detenmines 
whether the function is the back-up copy function or not 
(S120). If the function is the back-up copy function, the 
keystream E*3(KS) by decryption algorithm D^^aw ) with 
respect to the key infomnation Ak (8121), and then the 
decrypted keystream D^^Ak[E^(*^S)J decryption al- 
gorithm DSC^,((.) with respect to the key infomiation Al 
(SI 22). 

[0101] At this time, the keystream DSC^{dsc^,[EG 
(KS)]) decrypted in smart card 3 is transported to record- 
ing side (SI 23) and is input to copy protection processor 
8 through smart card 7 (SI 24) to then be encrypted by 
encryption algorithm ESC^,(.). 

[01 02] Accordingly, smart card 7 inserts the encrypted 
keystream DSC^|JeG(KS)] into a position designated by 
the index code IDX and mixes the same with the bit- 
stream Sks(BS) output from copy protection processor 
4 of playback side to then be recorded onto the tape in 
VCR 9. 

[0103] If it is determined that the operation is the re- 
cording operation in S1 19, and it is detennined in SI 20 
that the PPP function is adopted, instead of the back-up 
copy function ), smart card 3 decrypts the keystream E^ 
(KS) by decryption algorithm D^^^K-) with respect to the 
key infomiation A) (SI 22) and transports the decrypted 
key infomiation DSC^EG(KS)] to recording side (SI 23). 
[01 04] At this time, copy protection processor 8 of re- 
cording side, having received the keystream DsqAI[eG 
(KS)] through smart card 7 encrypts the received key- 
stream Dsc^[E^(KS)] by the encryption algorithm E^ 
and inserts the encrypted keystream [E^(KS)] into 
a position designated by the index code IDX, thereby 
mixing with the bitstream S,<s(BS) output from ccyy pro- 
tection processor 4 of playback side. Therefore, the bit- 
stream Sks(BS)+EG(KS) output from copy protection 
processor 8 is recorded onto the tape by VCR 9. 
[0105] As described above, in the preferred embodi- 
ment, all smart cards have common algorithm and com- 
mon key with respect to encryption algorithm EG(-) and 



decryption algorithm D%) for the MPEG bitstream. 
[0106] Also, the encryption algorithm E^aio and de- 
cryption algorithm D^c^j^^ for a smart card are common 
for all smart card. However, key infomnation is different 
5 for the respective smart cards. 

[0107] In other words, each smart card contains an 
authentication key corresponding to its own identifica- 
tion (ID) in itself. 

[0108] In performing such operation, the initialization 

10 including an authentication process for identify their 
counterpart between the copy protection processor and 
the smart card, and between the smart cards and a key 
exchange process is necessary. 
[0109] At this time, as the authentication process, 

'5 there has been proposed various methods such as a 
method of using symmetrical key algorithm like a DES 
algorithm, a method of using a public key algorithm like 
an RSA, or a method of using Fiat-Shamir (FS) scheme. 
[0110] In the described embodiment, the publfe key 

20 algorithm is used In the authentteation process and the 
key exchange method are illustrated In FIG. 21. Such 
methods are adopted on the basis that a public key (n. 
e) is shared by a key reception means 201 and a key 
transport means 202. 

25 [0111] Atthis time, key reception means 201 is a copy 
protection processor or a smart card 1 of recording side, 
and key transport means 202 is its own smart card k. 
[0112] The embodiment of the present invention op- 
erating as shown in the above flowchart will now be de- 

30 scribed with reference to FIGS, 1 2 through 1 8. 

[0113] In the embodiment as shown in FIG. 11 A, if 
non-scrambled bitstream BS is transported, the circuit 
operates as shown in FIG. 12. Therefore, the bitstream 
modulated/demodulated and RS-decoded in demodu- 

35 later & error corrector 1 is decrypted in ATV decoder 2, 
thereby outputting analog video and audio signals. 
[01 1 4] Atthis time, during recording operation, the bit- 
stream BS output from demodulator & error corrector 1 
is recorded onto the tape in VCR 5 through copy protec- 

40 tion processor 4. During playback operation, the bit- 
stream BS played back from VCR 5 is input to ATV de- 
coder 2 through copy protection processor 4 and is de- 
crypted, thereby outputting analog video and audio sig- 
nals. 

45 [01 1 5] In other words, since the data is not generated 
from copy protection processor 4 to smart card 3, the 
view and copy are not affected. 
[0118] As shown in FIGS. 11B and 11C, if scrambled 
bitstream is input, the CA function is adopted to perfonm 

50 the operations shown in FIGS. 13 through 18. 

[0117] First, in case of performing the PPV function, 
the circuit operates as shown in FIG. 13. That is to say, 
if scrambled bitstream S,^s(^) and encrypted key- 
stream EG(KS) are transported, demodulator & error 

55 corrector 1 demodulates the modulated input signal and 
then corrects the errors generated during transport 
through RS-decoding. 

[0118] At this time, ATV decoder 2 splits the key- 
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stream EG(KS) from the output Sks(BS)+EQ(KS) of de- 
modulator & error corrector 1 and outputs the same to 
smart card 3. Then , smart card 3 decrypts the encrypted 
keystream E*2(KS) and outputs again the keystream KS 
to ATV decoder 2. 

[0119] Accordingly, ATV decoder 2 reads the key in- 
formation KS of smart card 3, detemnines a descram- 
bling method and descrambles the bitstream Sks(BS) 
to output analog video and audio signals. 
[0120] As described above, smart card 3 shown in 
FIG. 9 allows processor 11 to decrypt the encrypted key- 
stream EG(KS) and to output the decrypted keystream 
KS to ATV decoder 2 by decryption algorithm E^(-). 
[0121] In the case of recording scrambled bitstream 
for the first time, the circuit operates as shown in FIG. 
1 4, in which the transported bitstream Sj^s{^)''"^^(KS) 
is errorcorrected in demodulator & enror corrector 1 
through RS-decoding and then is input to VCR 5 through 
copy protection processor 4 to then be recorded onto 
the tape. 

[0122] In the case of playing back the bitstream re- 
corded as described above, if the function is PPP func- 
tion, the system operates as shown in FIG. 15. If the 
bitstream Sks(BS)+EG(KS) played back from VCR 5 is 
input to copy protection processor 4, copy protection 
processor 4 splits the ptayed-back bitstream Sks(BS) 
+EG(KS) into the bitstream Sks(BS) and keystream E*^ 
(KS) and then again encrypts the split keystream E^ 
(KS) by encryption algorithm E^c^i^^.j to then output the 
same to smart card 3. The split bitstream S^sCBS) is out- 
put to ATV decoder 2 with the extracted portion of the 
keystream E®(KS) inserted with an index code IDX. 
[0123] At this time, smart card 3 having received the 
Index code IDX through ATV decoder 2, decrypts the 
encrypted keystream E^;^j([E®(KS)J of copy protection 
processor 2 by decryption algorithm D^;^^^.) for smart 
card and outputs the key stream (descrambling infomna- 
tion) KS to ATV decoder 2 (S1 1 7). 
[0124] Accordingly, ATV decoder 2 reads the key 
stream KS of smart card 3, determines a descrambling 
method and decrypts the bitstream S^sCBS) input 
through copy protection processor 4, thereby outputting 
analog video and audio signals. 
[0125] Also, in the case of recording the data recorded 
as shown in FIG. 1 4 onto a different VCR, the PPC func- 
tion is performed as shown In FIG. 16. If the bitstream 
Sks(BS)+EG(KS) played back from VCR 5 is input to 
copy protection processor 4, copy protection processor 
4 splits the bitstream Sks(BS)+E^(KS) into the bit- 
stream Sks(BS) and keystream E®{KS) and then again 
encrypts the split keystream E®(KS) by encryption algo- 
rithm E^y^i^.) to then output the same to smart card 3. 
The split bitstream Sks(BS) is output to copy protection 
processor 8 of recording side with the extracted portion 
of the keystream E®(KS) inserted with the index code 
IDX. 

[0126] At this time, smart card 3 of playback side de- 
crypts the keystream ESC;^k[EG(KS)] encrypted in copy 



protection processor 4 by decryption algorithm D^^ah ) 
with respect to the key information Al stored in RAM 15 
and then outputs the decrypted keystream D^c^fE® 
(KS)1 to smart card 7 of recording side. 

5 [0127] Accordingly, if smart card 7 of recording side 
receives the keystream DSC^EG(KS)) of smart card 3 
of playback side and outputs the same to copy protec- 
tion processor 8, copy protection processor 8 encrypts 
the keystream DSC^[eG(ks)] and restores the same in- 

10 to the original encrypted keystream EG(KS), which is 
mixed with the bitstream Gj^(BS) output from copy pro- 
tection processor 4 of playback side according to the 
index code IDX to then be output to VCR 9, thereby re- 
cording the same onto another tape. 

15 [0128] The data of the tape recorded in the above- 
described operations adopts the PPP function and is 
played back as shown in FIG. 15. 
[0129] Also, in the case of recording the data recorded 
as shown in FIG. 14 onto another VCR, the back-up 

20 copy function is performed as shown in FIG. 1 7, 

[0130] In other words, if the bitstream Sks(BS)+E® 
(KS) played back from VCR 5 is input to copy protection 
processor 4, copy protection processor 4 splits the bit- 
stream Sks(BS)+EG(KS) into the bitstream Sks(BS) and 

25 keystream EQ(KS) and then again encrypts the split key- 
stream EG(KS) by encryption algorithm E^^y^K^.j to then 
output the same to smart card 3. The split bitstream S^s 
(BS) is output to copy protection processor 8 of record- 
ing side with the extracted portion of the keystream E^ 

30 (KS) Inserted with the index code IDX. 

[0131] At this time, smart card 3 of playback side de- 
crypts twice the keystream E®^Ak[E®(KS)] encrypted in 
copy protection processor 4 by decryption algorithm D®" 
^fij^.) with respect to its own key information Ak stored in 

35 ROM 14 and then decrypts again by decryption algo- 
rithm D^c^jj with respect to the key Infomnation Al 
stored in RAM 15 and then outputs the decrypted key- 
stream DSC^DSC^k[E®(KS)]) to smart card 7 of record- 
ing side. 

40 [0132] Accordingly, if the keystream DSC^{DSC^[EG 
(KS)]} of smart card 3 of playback side is output to copy 
protection processor 8 of recording side through smart 
card 7 of recording side, copy protection processor 8 
encrypts the keystream DSC^|{DSC^eG(KS)]} with re- 

45 spect to the key infomnation Al and restores the same 
into the original encrypted keystream D^;yj[E*3(KS)]. 
The restored DSC^[E®(KS)] is mixed with the bitstream 
Gks(BS) output from copy protection processor 4 of 
playback side according to the index code IDX to then 

50 be output to VCR 9, thereby recording the same onto 
another tape. 

[0133] Here, the charge is counted in the improved 
smart card 3 or 7. 

[0134] The data recorded by performing the back-up 
55 copy function can be played back only from the VCR 
recording the original tape. In the case of a normal play- 
back, the operation is executed as shown in FIG. 1 8A. 
[0135] In other words, if the bitstream S|<s(BS)+DSC^ 



9 



17 



EP 0 714 204 B1 



18 



[E^(KS)] played back from VCR 5 is input to copy pro- 
tection processor 4, copy protection processor 4 spiits 
the bitstream SKs(BS)+DSC^k[EG{KS)] into the bit- 
stream Sks(^) keystream DSCaic[E^{*^S)1 
then again encrypts twice the split keystream DSC^^[eg 
(KS)] by encryption algorithm E^aw ) ^° t^®" output the 
same to smart card 3. The split bitstream 8^5(88) is out- 
put to ATV decoder 2 with the extracted portion of the 
keystream D^^AkL^^iKS)] inserted with the Index code 
IDX. 

[0136] At this time, smart card 3 having received the 
index code IDX through ATV decoder 2 decrypts twice 
the keystream E®^Ak[^^(*^S)] encrypted in copy protec- 
tion processor 2 by decryption algorithm D®^Ak(*) 
smart card and then outputs the key stream (descram- 
bling information) KS to ATV decoder 2. 
[0137] Accordingly, ATV decoder 2 reads the key 
stream KS of smart card 3, detemnlnes a descrambling 
method and decrypts the bitstream S,^s(BS) input 
through copy protection processor 4, thereby outputting 
analog video and audio signals. 
[0138] Also, in the case of an abnomnal playback to 
another VCR not to the original recorded VCR, the op- 
eration is executed as shown in FIG. 18B, thereby dis- 
abling the playback of the tape. 
[0139] In other words, ifthe copied tape is played back 
from VCR to which the tape copy has been performed, 
copy protection processor 8 splits the played-back data 
S|^s(BSKD^*^Ak[E^(*<S)] to separate the bitstream Sks 
(BS)+IDX. 

[0140] At this time, the split bitstream C^Ak[E^{KS)] 
is encrypted with respect to its own key infomriation Al 
and is again encrypted with respect to the key infomna- 
tion Al to become ESC^,{ESC^{DSC^eG{KS)])} to then 
be transported to smart card 7. 
[0141] At this time, smart card 7 cannot decrypt the 
keystream ESC^,{ESC^,(DSC^eG(KS)])}, sothatthe key 
information KS may not be transported to ATV decoder 
6. 

[0142] Accordingly, smart card 7 cannot descrambles 
the bitstream 81^3(88) so that the copied tape cannot be 
played back. 

[0143] As described above, since the authentication 
and key exchange process are automatically performed 
during power-on or connection between DVCRs, the il- 
legal view and copy protection function for illegal smart 
card can be automatically pertomned. Also, since the il- 
legal view and copy protection is partially performed, the 
scrambling process is performed with respect to a pro- 
tection-desired portion of a program, thereby performing 
the illegal view and copy protection automatically and 
levying the charge in a desirable manner. 
[0144] Also, in the described embodiment, since the 
split bitstream and keystream are transported to differ- 
ent paths, the protection data amount can be reduced, 
thereby efficiently performing the illegal view and copy 
protection. In implementing the illegal view protection 
and illegal copy protection for a smart card, the PPV, 



PPP, PPC and back-up copy functions are differentiat- 
ed, thereby levying the charges differentially for the re- 
spective functions. 

[0145] According to the described embodiment, the 
5 copyprotection for digital signals, which is adoptable for 

DSM applications can be implemented, which allows a 

program copyright protection for a DSM such as a 

DVCR. Therefore, the reliability for illegal view and copy 

protection is increased. 
10 [0146] Finally, in order to facilitate the understanding 

of the present invention, temris used in the specification 

will be defined as follows: 

1) 88: non-scrambled GA bitstream; 
15 2) KS=[Ko, K^ , K2.... K,,...Kn]: keystream (Here, n is 
total number of keys used for scrambling.); 
3) BS=[88o, 88^, BSg...- 88,, ...88 J: bitstream 
(Here, 88, is one segment of 88 and Is a scrambling 
unit.); 

20 4) Sks(B8)=[Sko(BSo), Ski{BS,), Sk2(8S2).... Sk, 
(B8j),...8Kn(8Sn)]: scrambled GA bitstream; 

5) E(-)&D(-): algorithms used for encryption and de- 
cryption of keys in GA; EG(KS)=[EG{Kq), EG(Ki), 
(K2),... EG(Ki),...EG(K„)] and DG[EG(KS)HDG[EG 

25 (Ko)], DG[EG(Ki)1, DG[EG(K2)1,... 
DG[EG(Ki)]....DG[EG(K„)]l=K8; 

6) 1DX=[0, 1 , 2,... I,... n]: index stream; 

7) Ak: authentication key for smart card (k); and 

8) ESc^(.)&DSC^(.): encryption and decryption algo- 
30 rithms for smart card used the smart card authenti- 
cation key (A) as the key. 

Claims 

35 

1 . An illegal view and copy protection method in a dig- 
ital video system comprising: 

a detemnination step for detemnining whether 
received data has been scrambled; 
a reproduction step, if the received data was 
detemiined to be scrambled data in the deter- 
mination step, splitting the scrambled data into 
a bitstream and a keystream for decrypting the 
split keystream for reading in key information, 
and descrambling the split bitstream according 
to the read in key infomiation for displaying the 
bitstream on a display; 

a recording step for, If the received data was 
determined to be scrambled data in the deter- 
mination step, recording the scrambled data on 
a recording medium either as scrambled data 
of a bitstream and a keystream according to a 
recording or copying mode, or after splitting the 
scrambled data into a bitstream and a key- 
stream, encrypting the split keystream, and 
mixing the encrypted keystream with the bit- 
stream; and, 
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5. An illegal view and copy protection nnethod in a dig- 
ital video system as claimed in claim 4, 
wherein said PPC mode operation the third step in- 
cludes. 

a first transportation step for transporting the 
scrambled data after splitting the bitstream and 
the keystream and inserting said index code in- 
to the split portion of said keystream, 
a second transportation step for transporting 
the keystream split in the first transportation 
step after encrypting the keystream with re- 
spect to its own key inf onmation and decrypting 
the same with respect to the key information 
from a recording side, 

a recording step for recording the keystream 
transported in the second transportation step 
on a recording medium after encrypting the 
keystream with respect to the key information 
from a recording side in con'espondence with 
the index code and mixing the same with the 
bitstream transported in the first transportation 
step. 



a transporting step, if the received data was de- 
tennlned to be scrambled data in the determi- 
nation step, splitting the scrambled data into a 
bitstream and a keystream for transporting the 
split keystream either after decrypting the split 
keystream with respect to key inf omnation from 
recording side according to a pay-per-copy 
(PPC) mode or a back-up copy mode, or after 
decrypting the split keystream two times with 
respect to key information contained therein 
and key information from recording side; 
thereby the reproduction step, the recording 
step and the transporting step can be per- 
fomned simultaneously or selectively. 

2. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 1 , wherein, if 
the received data was detenmined to be unscranr>- 
bled data in the determination step, said illegal view 
and copy protection method is not applied to the un- 
scrambled data. 

3. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 1 , wherein the 
reproduction step includes the step of decrypting 
said split keystream with a decryption algorithm, for 
reading in key inforrnation. 

4. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 1 , 
wherein a copying operation in the recording step 
includes, 

a first step for encrypting the key stream with 
respect to its own key information, 
a second step for determining the encrypted 
keystream of being a back-up copy mode or a 
PPC mode, 

a third step for, if the mode was determined to 
be the PPC mode in the second step encrypting 
the keystream transported after being decrypt- 
ed with respect to the key infomnation from a 
recording side, and then inserting the same into 
a position corresponding to an index code to 
record the same together with the bitstream, 
and 

a fourth step for, if the mode is determined to 
be the back-up copy mode in the second step, 
encrypting the keystream transported after be- 
ing decrypted with respect to Its own key infor- 
mation and the key information from a record- 
ing side 

decrypting the same with respect to its own 
key information, and then inserting the 
same into a position corresponding to an 
index code, to record the same together 
with the bitstream. 



25 6. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 5, 
wherein the reproduction operation after finish of 
the recording step includes, 

30 a splitting step for splitting the reproduced bit- 

stream into a bitstream and a keystream and 
Inserting an index code into the split portion of 
the keystream, 

an encrypting step for encrypting the keystream 
55 split in the splitting step with respect to its own 

key information, 

a reading in step for reading in key infomnation 
by decirypting the keystream encrypted In the 
encrypting step, with respect to its own key in- 
^0 fomnation, and 

a decrypting step for descrambling the bit- 
stream split according to the key infomnation 
read in in the reading in step. 

7. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 4, 
wherein said back-up copy mode operation in the 
fourth step includes, 

50 a first transportation step for transporting the 

scrambled data after splifting the scrannbled da- 
ta into a bitstream and a keystream and insert- 
ing an index code into the split portion of the 
keystream, 

55 a second transportation step for transporting 

the keystream split in the first transportation 
step after encrypting the keystream with re- 
spect to Its own key inf omriation and decrypting 
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the encrypted keystream with respect to the key 
information from a recording side and Its own 
key infonnation, 

a recording step for recording the keystream 
transported in the second transportation step 5 
on a recording medium after encrypting the 
keystream with respect to the key information 
from a recording side in correspondence with 
the index code and mixing the same with the 
bitstream transported in the first transportation io 
step. 

8. An 11 legal view and copy protection method in a dig- 
ital video system as claimed in claim 7, 

wherein the reproduction operation after finish of is 
the recording step includes, 

a splitting step for splitting the reproduced bit- 
stream into a bitstream and a keystream and 
inserting an index code into the split portion of 20 
the keystream, 

an encrypting step for encrypting the keystream 
spirt In the splitting step with respect to its own 
key information, 

a reading in step for reading in key infomnation 25 
by decrypting the keystream encrypted for two 
times in the encrypting step, with respect to its 
own key information and the MPEG bitstream, 
and 

a decrypting step for descrambling the bit- 30 
stream split according to the key infomiation 
read in in the reading in step. 

9. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 1 , wherein the 35 
transporting step comprises: 

a mode detemnining step for determining the 
mode of the keystream being a back-up copy 
mode or a PPC mode; 40 
a first keystream transportation step for, if the 
mode was determined to be a PPC mode in the 
mode detemnining step, decrypting the key- 
stream with respect to key information from a 
recording side for transporting the keystream; 45 
a first transporting recording step for encrypting 
the keystream transported in the first key- 
stream transportation step with respect, to the 
key infomnation from the recording side and in- 
serting the encrypted keystream into a position so 
designated by an index code, for recording the 
keystream together with a bitstream on a re- 
cording medium; 

a second keystream transportation step for. if 
the mode was determined to be a back-up copy 55 
mode in the detenmining step, decrypting the 
keystream for two times with respect to its own 
key information and the key information from 



the recording side for transporting the key- 
stream; and 

a second transporting recording step for en- 
crypting the keystream transported in the sec- 
ond keystream transportation step with respect 
to the key infomnation from the recording side 
and inserting the encrypted keystream into the 
position corresponding to the index code, for re- 
cording the keystream together with the bit- 
stream on a recording medium. 

10. An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 9, 
wherein the first keystream transportation step in- 
cludes the steps for decrypting the keystream, en- 
crypted with respect to its own key infomnation, with 
respect to its own key infomnation and decrypting 
the keystream again with respect to the key infor- 
mation from the recording side, for transporting the 
keystream. 

11 . An illegal view and copy protection method in a dig- 
ital video system as claimed in claim 9, 
wherein the second keystream transportation step 
includes the step for decrypting the bitstream, de- 
crypted with respect to its own key information, for 
two times with respect to its own key information 
and decrypting the keystream again with respect to 
the key infomnation from the recording side for 
transporting the keystream. 

12. An illegal view and copy protection method in k 
digitalvideo system as claimed in claim 1 , wherein 
the reproduction step further comprises: 

a 'PPC mode reproduction step for, having de- 
temnined the recording medium being a 'PPC 
recording medium on detection of a keystream 
at reproduction from a recording medium, en- 
crypting the keystream with respect to its own 
key infomnation and decrypting the keystream 
with respect to its own key information for read- 
ing in the key information, for descrambling the 
bitstream using both the read in key infomnation 
and an index code; and, 
a 'back-up copy* mode reproduction step for, 
having detemnined the recording medium being 
a 'back-up cop/ recording medium on detec- 
tion of a keystream decrypted with respect to 
its own key information at reproduction from a 
recording medium, encrypting the keystream 
for two times with respect to its own key infor- 
mation and the key information from a record- 
ing side and decrypting the keystream with re- 
spect to its own key infomiation for reading in 
the key information, for descrambling the bit- 
stream using both the read in key information 
and an index code. 
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13. A digital video system including an illegal view and 
copy protection device, the device comprising 
means for carrying out the method steps of any of 
claims 1 to 12. 



PatentansprOche 

1 . Verfahren zum Schutz vor unerlaubtem Sehen und 
Kopieren in einem digltalen Videosystem, umfas- 
send: 

einen Bestimmungsschritt zum Bestimmen, ob 
empfangene Daten verwurfett wurden; 

einen Wtederhersteltungsschritt, der, wenn in 
dem Bestimmungsschritt bestimmt wurde, daR 
die empfangenen Daten verwurfelt sind, die 
verwurfeiten Daten in einen Bitstrom und einen 
Schlusselstrom aufteilt, um den abgeteitten 
Schliisselstrom zu entschlussetn und um dann 
Schliisselinfomriation einzulesen, und um den 
abgeteilten Bitstrom entsprechend dereingele- 
senen Schlusselinfomnation zu entwurfein, um 
den Bitstrom auf einer Sichtanzeige darzuste!- 
len; 

einen Aufnahmeschritt, um, wenn in dem Be- 
stimmungsschritt bestimmt wurde, da3 die 
empfangenen Daten verwurfelte Daten sind, 
die verwurfeiten Daten auf einem Aufnahme- 
medium aufzunehmen, und zwar entweder als 
verwurfelte Daten eines Bitstroms und eines 
Schliisselstroms entsprechend einer Aufnah- 
me- Oder Kopierbetriebsart, oder, nach Auftei- 
lung der verwurfeiten Daten in einen Bitstrom 
und einen Schlusselstrom, zum Verschlusseln 
des abgeteilten Schlusselstroms und Mischen 
des verschlussetten Schlusselstroms mit dem 
Bitstrom; und 

einen Befdrderungsschritt, der, wenn im Be- 
stimmungsschritt bestimmt wurde, daB die 
empfangenen Daten verwurfelte Daten sind, 
die verwurfeiten Daten zum Befdrdem des ab- 
geteilten Schlusselstroms in einen Bitstrom 
und einen Schlusselstrom aufteilt, und zwar 
entweder nach dem Entschlussetn des abge- 
teilten Schlusselstroms in bezug auf die 
Schlusselinfomiation von der Aufnahmeserte 
her entsprechend einer Bezahl-pro-Kopie (pay- 
per-copy, PPC) -Betriebsart oder entsprechend 
einer Sicherungskopre-Betriebsart, oder nach 
dem zweimaligen Entschlussein des abgeteil- 
ten Schlusselstroms in bezug auf die darin ent- 
haltene Schlusselinfomnation und die Schlus- 
selinfomnation von der Aufnahmeseite her; 



dabei konnen der Wiederherstellungsschritt, 
der Aufnahmeschritt und der Befdrderungs- 
schritt gleichzeitig oder wahlweise ausgefuhrt 
werden. 

5 

2. Verfahren zum Schutz vor unerlaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 1, worin, wenn Im Bestimmungaschritt be- 
stimmt wurde, daS die empfangenen Daten unver- 

10 wurfelte Daten sind, das Verfahren zum Schutz vor 
uneriaubtem Kopieren und Sehen nicht auf die un- 
venvurfelten Daten angewendet wird. 

3. Verfahren zum Schutz vor uneriaubtem Sehen und 
IS Kopieren in einem digitalen Videosystem nach An- 

spruch 1 , worin der Wiederherstellungsschritt den 
Schritt zum Entschlussetn des abgeteilten Schlus- 
selstroms mit einem Entschlusselungsalgorithmus- 
ses zum Einlesen von Schlusselinformation um- 
20 fasst. 

4. Verfahren zum Schutz vor uneriaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 1 , worin ein Kopiervorgang In dem Aufnah- 

25 meschritt folgende Schritte beinhattet: 

einen ersten Schritt zum verschlusseln des 
Schlusselstroms in bezug auf seine eigene 
Schlusselinformation, 

30 

einen zweiten Schritt zum Bestimmen, ob der 
des verschlusselte Schlusselstrom in einer Si- 
cherungskopie-Betriebsart oder einer PPC-Be- 
triebsart voriiegt, 

35 

ieinen dritten Schritt, um, wenn im zweiten 
Schritt bestimmt wurde, dal3 die Betriebsart ei- 
ne PPC Betriebsart ist, den Schlusselstrom zu 
verschlusseln, welcher nach Entschlusselung 

^0 in bezug auf die Schlusselinfomnation von einer 

Aufnahmeseite her befordert wurde, und um 
dann denselben in eine Position einzufugen, 
die einer Indexkennung entspricht, um densel- 
ben zusammen mit dem Bitstrom aufzuneh- 

45 men, und 

einen vierten Schritt, um, wenn im zweiten 
Schritt bestimmt wurde, daB die Betriebsart ei- 
ne Sichemngskopie-Betriebsart ist, den nach 

50 seiner Entschlusselung transportierten Schlus- 

selstrom in bezug auf seine eigene Schlusset- 
infonnation und die Schlusselinformation von 
einer Aufnahmeseite herzu verschlusseln, und 
um denselben in eine Position entsprechend ei- 

55 ner Indexkennung einzufugen, um denselben 

zusammen mit dem Bitstrom aufzunehmen. 

5. Verfahren zum Schutz vor uneriaubtem Sehen und 
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Kopieren in einem digitalen Videosystem nach An- 
spruch 4, worin die PPC-Betriebsart des dritten 
Schrittes folgendes betnhaftet: 

einen ersten Beforderungsschritt zum Befor- 5 
dem der verwurfelten Daten nach Aufteilung 
des Bitstronns und des Schlusselstroms und 
Einfugen der Indexkennung in den abgeteilten 
Tel! des Schlusselstroms, 

10 

einen zweiten Beforderungsschritt zum Befor- 
dern des Schlusselstroms, welcher im ersten 
Beforderungsschritt abgeteilt wurde, nachdem 
der Schlusselstrom in bezug auf seine eigene 
Schlusselinfonnation verschlusselt wurde und '5 
derselbe In bezug auf die Schlusselinfonnation 
von einer Aufnahmeseite her entschlussett 
wurde, 

einen Aufnahmeschritt zur Aufnahme des 20 
Schlusselstroms, welcher im zweiten Beforde- 
rungsschritt nach Verschliisselung des Schlus- 
selstroms in bezug auf die Schlusselinfomnati- 
on von einer Aufnahmeseite her in Zuordnung 
mit der Indexkennung auf einen Aufzeich- 25 
nungstrager befordert wurde, und zum Mi- 
schen desselben mtt dem im ersten Beforde- 
rungsschritt beforderten Bitstrom. 

Verfahren zum Schutz vor uneriaubtem Sehen und 30 
Kopieren in einem digitalen Videosystem nach An- 
spruch 5, worin der Wiedergabebetrieb nach Ab- 
schluss des Aufnahmeschrittes folgendes beinhal- 
tet: 

35 

einen Aufteilungsschritt zur Aufteilung des wie- 
dergegebenen Bitstroms in einen Bitstrom und 
einen Schlusselstrom und Einfugen einer In- 
dexkennung in den abgeteilten Teil des Schlus- 
selstroms, 40 

einen verschlusselungsschritt zum Verschlus- 
seln des Schlusselstroms, welcher im Auftei- 
lungsschritt in bezug auf seine eigene Schlus- 
selinfonnation abgeteilt wurde, 45 

ein Einleseschritt zum Einlesen der Schlussel- 
infonnation durch Entschlusseln des Schlus- 
selstroms, welcher im Verschlusselungsschritt 
In bezug auf seine eigene Schlusselinfonnation so 
verschlusselt wurde, und 

einen Entschlusselungsschritt zum Entwurfeln 
des Bitstroms, welcher gemaB der im Einlese- 
schritt eingelesenen Schlusselinfonnation ab- 55 
geteilt wurde. 

Verfahren zum Schutz vor uneriaubtem Sehen und 



Kopieren In einem digitalen Videosystem nach An- 
spruch 4, worin die Sichenjngskople-Betriebsart im 
vierten Schritt folgende Schritte beinhaltet: 

einen ersten Beforderungsschritt zum Befor- 
dem der verwurfelten Daten nach Aufteilung 
der venvurfelten Daten in einen Bitstrom und 
einen Schlusselstrom und Einfugen einer In- 
dexkennung In den abgeteilten Teil des Schlus- 
selstroms, 

einen zweiten Beforderungsschritt zum Befor- 
dem des Schlusselstroms, welcher im ersten 
Beforderungsschritt abgeteilt wurde nach Ver- 
schliisselung des Schlusselstromes In bezug 
auf seine eigene Schlusselinfonnation und zum 
Entschlusseln des verschliisselten Schlussel- 
stromes in bezug auf die Schlusselinformation 
von einer Aufnahmeseite und seiner eigenen 
Schlusselinformation her, 

einen Aufnahmeschritt zum Aufnehmen des 
Schlusselstromes, welcher im zweiten Befor- 
demngsschrltt befordert wurde auf ein Aufnah- 
memedium nach Verschlusselung des Schlus- 
selstromes in bezug auf die Schlusselinfonna- 
tion von einer Aufnahmeseite her in Zuordnung 
mit der Indexkennung und nach Mischen des- 
selben mit dem Bitstrom, wek?her im ersten Be- 
forderungsschritt befordert wurde. 

8. Verfahren zum Schutz vor uneriaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 7, worin der Wiedergabebetrieb nach Been- 
den des Aufnahmeschrittes folgende Schritte be- 
inhaltet: 

einen Aufteilungsschritt zur Aufteilung des wie- 
dergegebenen Bitstromes in einen Bitstrom 
und einen Schlusselstrom und zum Einfugen 
einer Indexkennung in den abgeteilten Teil des 
Schlusselstromes, 

einen Verschlusselungsschritt zum Verschlus- 
seln des Schlusselstromes, welcher im Auftei- 
lungsschritt in bezug auf seine eigene Schlus- 
selinformation abgeteilt wurde, 

einen Einleseschritt zum Einlesen von Schlus- 
selinfonnation durch Entschlusseln des 
Schlusselstromes, welcher zweimalig im Ver- 
schlusselungsschritt in bezug auf seine eigene 
Schlusselinfonnation und den MPEG Bitstrom 
verschlusselt wurde, und 

einen Entschlusselungsschritt zum Entschlus- 
seln des Bitstromes, welcher entsprechend der 
im Einleseschritt eingelesenen Schlusselinfor- 
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mation abgeteilt wurde. 

9. Vertahren zum Schutz vor unerlaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 1 , worin der Beforderungsschritt umfasst: 

einen Betriebsart-bestimmenden Schritt zum 
Bestimmen der Betriebsart des Schlusselstro- 
mes, welche eine Sichemngskopie-Betriebsart 
Oder eine PPC Betriebsart ist; 

einen ersten Schlusseistrom-Befordenings- 
schritt, urn, wenn im Betriebsart-bestimmen- 
den Schritt bestimmt wurde, daB die Betriebs- 
art eine PPC-Betriebsart ist, den Schlussel- 
strom in bezug auf die Schlusselinfomriation 
von einer Aufnahmeseite her zum Befordern 
des Schlussetstromes zu entschlussein; 

einen ersten Beforderungsaufnahmeschritt, 
urn den schlussetstrom, welcher im ersten 
Schlusselstrom-Beforderungsschritt in bezug 
auf die Schlussellnformation von der Aufnah- 
meseite her befordert wurde zu verschlussetn, 
und um den verschlusselten Schlusselstrom in 
eine Position einzufOgen, welche durch eine tn- 
dexkennung bestimmt ist, und um den Schlus- 
selstrom zusammen mit einem Bitstrom auf ein 
Aufnahmemedium aufzunehmen; 

einen zweiten Schlusselstrom-Befordemngs- 
schritt, um, wenn im Bestimmungsschritt be- 
stimmt wurde, daB die Betriebsart eine Siche- 
rungskopie-Betriebsart ist, den Schlusselstrom 
zweimalig in bezug auf seine eigene Schlussel- 
infomnation und die Schlussel information von 
der Aufnahmeseite her zum Befordern des 
Schlusselstromes zu entschlussein; und 

einen zweiten Beforderungs-Aufnahme- 
Schritt, um den Schlusselstrom, welcher im 
zweiten Schlusselstrom-Betorderungsschritt in 
bezug auf die Schlussellnformation von der 
Aufnahmeseite her befordert wurde, zu ver- 
schlussetn, und um den verschlusselten 
Schlusselstrom in die Position entsprechend 
der Indexkennung einzufugen, und um den 
Schlueselstrom zusammen mit dem Bitstrom 
auf ein Aufnahmemedium aufzunehmen. 

10. Verfahren zum Schutz vor uneriaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 9, worin der erste Schtusselstrom-Beforde* 
rungsschritt die Schritte zur Entschlusselung des 
Schlusselstromes in bezug auf seine eigene 
Schlussellnformation beinhaltet, welcher In bezug 
auf seine eigene Schlusselinfomriation verschlus- 
selt wurde, und um den Schlusselstrom wieder in 
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bezug auf die Schlusselinf omnation von der Aufnah- 
meseite her zu entschlussein, und um den Schlus- 
selstrom zu befordern. 

11 . Verfahren zum Schutz vor uneriaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 9, worin der zwerte Schlusselstrom-Befor- 
derungsschritt den Schritt zur zweimaligen Ent- 
schlusselung des Bitstromes in bezug auf seine ei- 
gene Schlussellnformation beinhaltet, welcher in 
bezug auf seine eigene Schlusselinfonnation ent- 
schtusselt wurde, und um den Schlusselstrom wie- 
der in bezug auf die Schlusselinfomriation von der 
Aufnahmeseite her zum Befordem des Schlussel- 
stromes zu entschlussein. 



25 



12. Verfahren zum Schutz vor uneriaubtem Sehen und 
Kopieren in einem digitalen Videosystem nach An- 
spruch 1 , worin der Wiedergabeschritt femer unrv 
20 fasst: 



einen 'PPC-Betriebsart-Wiedergabeschritt, 
um, wenn bei Nachweis eines Schlusselstro- 
mes bei Wiedergabe von einem Aufnahmeme- 
dium bestimmt wurde, daB das Aufnahmeme- 
dium ein 'PPC'-Aufnahmemedium ist, den 
Schlusselstrom in bezug auf seine eigene 
Schlussellnformation zuverschlussein, und um 
den Schlusselstrom in bezug auf seine eigene 
Schlusselinfomriation zum Einlesen der Schlus- 
selinfomriation zu entschlussein, und um den 
Bitstrom unter Verwendung sowoh! der einge- 
lesenen Schlusselinfonmation und einer Index- 
kennung zu entwurfein; und 
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einen 'Sicherungskopie'-Betriebsart-Wieder- 
gabeschritt, um, wenn bei Nachweis eines 
Schlusselstromes bei Wiedergabe von einem 
Aufnahmemedium bestimmt wurde, daB das 
Aufnahmemedium ein *Sk;herungskopie'- Auf- 
nahmemedium ist, den Schlusselstrom zwei- 
malig in bezug auf seine eigene Schlusselinfor- 
mation und der Schlussellnformation von einer 
Aufnahmeseite her zu verschlussetn, und um 
den Schlusselstrom in bezug auf seine eigene 
Schlussel infomnation zum Einlesen der Schlus- 
sellnformation zu entschlussein, und um den 
Bitstrom unter Verwendung sowohl der Einle- 
seschlusselinfomnation und einer Indexken- 
nung zu entwurfein. 



13. Digitales Videosystem mit einem Gerat zum Schutz 
vor uneriaubtem Sehen und Xopieren, wobei das 
Gerat Mittel zur Ausfuhrung der Verfahrensschritte 
55 nach den Anspruchen 1 bis 12 unnfasst. 
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Revendications 

1 . Un proc6d6 de protection contre le vision nage et la 

copie illegaux dans un systeme de video num6rique 3. 
comprenant : 5 

une 6tape consistant k determiner si des don- 
nees regues sont brouillees ou pas; 
dans le cas ou it a ^le d^temnin^ dans )*6tape 
de d^tennination que les donn^es regues sont io 
des donn^es brouilldes, une 6tape de repro- 
duction consistant ^ s^parer les donnees 4. 
brouillees en un flux de bits et un flux de cles 
de cryptage pour le decryptage du flux de cl^s 
de cryptage ainsi s6par6 pour la lecture des in- 15 
fonmalions sur la cl6, et pour d6crypter le flux 
de bits ainsi s§par6 au moyen des infonnations 
de c\6 lues pour I'affichage du flux de bits sur 
un organe d'affichage ; 

dans le cas ou il a ete determine k I'^tape de 20 
detemriination que les donn6es regues sont des 
donnees brouiil6es, une 6tape d'enregistre- 
ment des donnees brouillees sur un support 
d'enregistrement soit sous foime de donnees 
brouillees composees d'un flux de bits et d'un 25 
flux de cl6s de cryptage correspondant k un 
mode d'enregistrement ou un mode de copie, 
ou, apres avoir separe les donnees brouillees 
en un flux de bits et un flux de cles de cryptage, 
k effectuer le cryptage du flux de cies de cryp- so 
tage ainsi s6par6, avec melange du flux de cies 
de cryptage ainsi crypte avec le flux de bits ; et 
dans le cas ou t) a ete determine tors de I'etape 
de detemnination que ies donnees revues sont 
des donnees brouillees, une etape de transport 35 
consistant k divisor les donnees brouillees en 
un flux de bits et un flux de cles de cryptage 
pour le transport du flux de cies de cryptage ain- 
si separe apres avoir, soit decrypte le flux de 
cies ainsi separe en utilisant des informations 
de cle obtenues du cote de I'enregistrement en 
mode paiement par copie (PPC) ou un mode 
de copie de sauvegarde, soit apres avoir de- 
crypte deux fois le flux de cies separe en utili- 
sant des informations de cie qui y sont conte- 45 
nues ainsi que des infomrtations de cie venant 
du cote de I'enregistrement; 5. 

de sorte que I'etape de reproduction, I'etape d'en- 
registrement et I'etape de transport puissent etre ef- so 
fectuees simultanement ou selectivement. 

2. Un precede de protection contre le visionnage et la 
copie iliegaux dans un systeme de video numerique 
selon la revendication 1, dans lequel, dans le cas ss 
ou il a ete determine au niveau de I'etape de deter- 
mination que les donnees regues sont des donnees 
non brouillees, led it precede de protection contre le 



visionnage et la copie iliegaux n'est pas applique 
aux donnees non brouillees. 

Un procede de protection contre le visionnage et )a 
copie iliegaux dans un systeme de video numerique 
selon la revendication 1 , dans lequel I'etape de re- 
production comprend I'etape consistant k decrypter 
le flux de cies de cryptage ainsi separe au moyen 
d'un algorithme de decryptage, pour la lecture des 
Infomnations de cie. 

Un procede de protection contre le visionnage et la 
copie iliegaux dans un systeme de video numerique 
selon la revendication 1 , dans tequel une operation 
de copie lors de I'etape d'enregistrement 
comprend : 

une premiere etape'pour crypter le flux de cl6s 
au moyen de sa propre infonnation de cie ; 
une deuxieme etape consistant ^ detemniner si, 
en ce qui concerne le flux de cies de cryptage, 
il s'agit d'un mode de copie de sauvegarde ou 
d'un mode de paiement k la copie (PPC) ; 
une troisleme etape pemnettant si, lors de la 
deuxieme etape il a ete detemnine qu'il s'agit 
d'un mode de paiement k la copie (PPC), de 
crypter le flux de cies de cryptage transporte 
apres avoir ete decrypte au moyen desa propre 
information de cles venant du cote de i'enregis- 
trement, suivie de I'insertion de ce flux dans 
une position con-espondant ^ un code d'index 
afin d'enregistrement ce flux avec le flux de 
bits ; et 

une quatrieme etape pemiettant, dans le cas 
ou il a ete detemnine lors de la deuxieme etape 
qu'il s'agit d'un mode de copie de sauvegarde, 
de crypter le flux de cies de cryptage transporte 
apres decryptage au moyen de sa propre infor- 
mation de cies et I'information de cies du cote 
de I'enregistrement au moyen de I'infomnation 
de cle du cote de Tenregistrement, et k decryp- 
ter ce flux au moyen de sa propre infomnation 
de cie, et k ins6rer ensuite ce flux dans une po- 
sition correspondant k un code d'index, afin 
d'enregistrer ce flux avec le flux de bits. 

Un procede de protection contre le visionnage et la 
copie iliegaux dans un systeme de video numerique 
selon la revendication 4, dans tequel, dans le cas 
d'un mode de f onctionnement k paiement k la copie 
(PPC), la troisieme etape comprend : 

u ne premiere etape de transport pour transpor- 
ter les donnees brouillees apres separation du 
flux de bits et du flux de cies de cryptage avec 
insertion dudit code d'index dans la partte se- 
paree dudit flux de ctes de cryptage ; 
une deuxieme etape de transport pour trans- 
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porter le flux de cl^ de cryptage separ^ lors de 
la premiere etape de transport apres le crypta- 
ge du flux de cl^ au nrtoyen de sa propre infor- 
mation de cles, et en decryptant ce flux au 
moyen de rinfonnation de cles venant du cote s 
de renregistrement ; 

une etape d'enregistrement pour enregistrer te 
flux de cl^s transports lors de la deuxi&me 6ta- 
pe de transport sur un support d*enregistre- 
nnent aprds cryptage du flux de cISs en fonctlon 
de t'Infonnation de cl6s venant du cdt6 de ren- 
registrement en correspondance avec le code 
d'index avec melange de ce flux avec le flux de 
bits transporte lors de la premiere dtape de 8. 
transport. t5 

Un procSde de protection centre le vislonnage et la 
copie nidgauxdans un syst^me de vidSo numerique 
selon la revendlcatlon 5, dans lequel I'operation de 
reproduction aprfes la fin de l'6tape d'enregistre- 20 
ment comprend : 

une etape de separation pour sSparer le flux de 
bits reprodurt en un flux de bits et un flux de cISs 
de cryptage avec Insertion d'un code d'index 25 
dans la partie sSparde du flux de cle de 
cryptage ; 

une 6tape de cryptage pour crypter le flux de 
cl6s de cryptage separ6 lors de t'etape de se- 
paration, au moyen de sa propre infomr^tion de so 
cles ; 

une Stape de lecture de donnSes pour la lecture 
de Hnformation de cl6s par decryptage du flux 
de cISs de cryptage crypte lors de I'etape de 
cryptage par rapport a sa propre information de 35 
cl6s ; et 

une 6tape de decryptage pour dSsembrouiller 
!e flux de bits separe, au moyen de I'infonnation 9. 
de cles lue tors de I'etape de lecture de don- 
n6es. 40 

Un procSdS de protection contre le vislonnage et la 
copie ill§gaux dans un systems de video numerique 
selon la revendication 4, dans lequel le fonctionne- 
ment dudit mode de copie de sauvegarde lors de la <s 
quatridme etape comprend : 

une premiere etape de transport pour le trans- 
port de donnSes brouillSes apr^s avoir sdparS 
les donndes brouilides en un flux de bits, et un 50 
flux de cles de cryptage avec insertion d'un co- 
de d'index dans la partie divisSe du flux de cies 
de cryptage ; 

une deuxieme etape de transport pour trans- 
porter le flux de cl6s de cryptage separe lors de 55 
la premiere Stape de transport apres cryptage 
du flux de cl6s de cryptage au moyen de sa pro- 
pre infomnation de cl6s et pour d6crypter le flux 



de cl6 de cryptage crypt6 au moyen de Tinfor- 
mation de cles venant du c6t6 de I'enregistre- 
ment et sa propre information de cl6s ; 
une etape d'enregistrement pour enregistrer le 
flux de cles de cryptage transporte lors de la 
deuxieme etape de transport sur un support 
d'enregistrement aprfes cryptage du flux de cles 
de cryptage au moyen de rinfonmation de cl6s 
venant du c6t6 de I'enregistrement, en corres- 
pondance k un code d'index, avec melange de 
ce flux avec le flux de bits transports lors de la 
premidre etape de transport. 

Un procSdS de protection contre le vislonnage et la 
copie illegaux dans un systeme de vidSo numerique 
selon ta revendication 7, dans lequel t'opSration de 
reproduction apres la fin de I'Stape d'enregistre- 
ment comprend : 

une 6tape de separation pour sSparer le flux de 
bits restitue en un flux de bits et un flux de cISs 
de cryptage avec insertion d'un code d'index 
dans la partie separSe du flux de cles de 
cryptage ; 

une etape de cryptage pour crypter le flux de 
cies de cryptage separe tors de I'etape de se- 
paration au moyen de sa propre infonmation de 
cies ; 

une etape de lecture de donnees pour lire Hn- 
fomnation de cies en decryptant le flux de cies 
de cryptage crypte deux fois lors de I'etape de 
cryptage, au moyen de sa propre information 
de cie et le flux de bits MPEG ; et 
une etape de decryptage pour desembrouiller 
le f lux de bits separe, au moyen de 1' infonmation 
de cie lue lors de I'etape de lecture de donnSes. 

Un precede de protection contre le vision nage et la 
copie iliegaux dans un systeme de video numerique 
selon la revendication 1, dans lequel I'etape de 
transport comprend ; 

une etape de determination de mode pour de- 
tenrtiner si le flux de ctes de cryptage est en 
mode de copie de sauvegarde ou d'un mode 
de paiement k la copie ; 
une premiere etape de transport de flux de cies 
de cryptage pour, dans le cas ou II a ete deter- 
mine lors de I'etape de detemnination qu'il s'agit 
d'un mode de paiement k la copie (PPC), de- 
crypter te flux de cies de cryptage au moyen de 
I'informatton de cies venant du cote de I'enre- 
gistrement, pour le transport du flux de cies de 
cryptage ; 

une premiere etape d'enregistrement de trans- 
port pour crypter le flux de cies de cryptage 
transporte lors de la premiere etape de trans- 
port de flux de ctes de cryptage au moyen de 
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rinformation de cle provenant du c6t6 de I'en- 
registrement avcc insertion du flux de c!6s de 
cryptage crypt6 dans une position designee par 
un code d'index, pour en registrar te flux de cl6s 
de cryptage avec le ftux de bits sur un support 5 
tfenregistrement ; 

une deuxidme etape de transport de flux de 
cl^s de cryptage pour, iorsqu'i) a d^termin^ 
iors de I'^tape de determination qu'il s'agit d'un 
mode de copie de sauvegarde. d^crypter le flux io 
de cles de cryptage deux fois au moyen de sa 
propre infonmation de cl6s ainsi que {"infonma- 
tion de cl6s venant du c6t6 de I'enreglstrement 
pour transporter le flux de cles de cryptage ; et 
une deuxi^me etape d'enregistrement de is 
transport pourcrypter le flux de cles de crypta- 
ge transports Iors de la deuxi6me 6tape de 
transport de flux de cles de cryptage au moyen 
de rinfomnation de cl§s venant du c6t6 de I'en- 
reglstrement et pour insurer le flux de cles de 20 
cryptage crypt6 dans la position con-espondant 
au code d'index, pour enregistrer le flux de cl6 
de cryptage avec le flux de bits, sur un support 
d'enregistrement 

25 

10. Un proc6d6 de protection centre le visionnage et la 
copie illegaux dans un systeme de video numerique 
selon la revendication 9, dans lequel ta premiere 
etape de transport de flux de cles de cryptage com- 
prend les Stapes consistant k dScrypter le flux de 30 
cl6s de cryptage, cryptS au moyen de sa propre in- 
formation de cl6s, moyennant sa propre information 

de cles et k decrypter encore une fois le flux de cles 
de cryptage au moyen de la c\6 d'information venant 
du c6t6 de Tenregistrement, pour le transport du flux 35 
de cles de cryptage. 

1 1. Un procede de protection centre le visionnage et la 
copie illSgaux dans un systSme de vidSo numSrique 
selon la revendication 9, dans lequel la deuxieme 40 
etape de transport de flux de cles de cryptage com- 
prend Tetape consistant k decrypter le flux de cl6s 

de cryptage, dScrypte au moyen de sa propre infor- 
mation de cl6s, deux fois, une premifere fois au 
moyen de sa propre information de cl6s et une 45 
deuxifeme fois au moyen de rinfomnation de cl6s ve- 
nant du cots de Penregistrement, pour le transport 
du flux de cISs de cryptage. 

12. Un procede de protection contre le visionnage et la so 
copie illegaux dans un systeme de video numerique 
selon la revendication 1 , dans lequel i'Stape de res- 
titution comprend en outre : 

une Stape de restitution du mode "paiement k 55 
la copie" (PPC) pour, apres avoir detemitne 
qu'il s'agit d'un support d'enregistrement en 
mode "paiement a la copie" suite a la detection 



d'un flux de cISs de cryptage Iors de la lecture 
du support d'enregistrement, crypter le flux de 
cISs de cryptage au moyen de sa propre infor- 
mation de cl6s et k dScrypter le flux de cISs de 
cryptage au moyen de sa propre infomnation de 
cISs pour la lecture de I'lnfonnation de cles, 
pour le dSsembrouillage du flux de bits en uti- 
llsant rinformation de cISs ainsi lue et un code 
d'index ; et 

une Stape de restitution en mode "copie de sau- 
vegarde", apres avoir determine qu'il s'agit d'un 
support d'enregistrement pur un mode "copie 
de sauvegarde", suite k la detection d'un flux 
de des de cryptage decrypts au moyen de sa 
propre infonnnation de cles Iors de ta lecture k 
partir d'un support d'enregistrement, pourcryp- 
ter le flux de cISs de cryptage deux fois au 
moyen de sa propre infomnation de cISs, et Tin- 
formation de cles venant du cotS de I'enregis- 
trement et pour dScrypter le flux de cles de 
cryptage au moyen de sa propre infonnation de 
cISs pour la lecture de I'infomnation de cISs, 
pour desembrouiller le flux de bits en utilisant 
rinfomnation de cles ainsi lue et un code d'in- 
dex. 

13. Un systeme de video numerique comprenant un 
disposttif de protection contre le visionnage et la co- 
pie illSgaux, le dispositif comprenant des moyens 
pour mettre en oeuvre les Stapes du procSdS selon 
I'une quelconque des revendications 1 a 12. 
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